Show filters
1,423 Total Results
Displaying 51-60 of 1,423
Sort by:
Attacker Value
Unknown

CVE-2023-25454

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in Nate Reist Protected Posts Logout Button allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Protected Posts Logout Button: from n/a through 1.4.5.
0
Attacker Value
Unknown

CVE-2023-25048

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in Fantastic Plugins Fantastic Content Protector Free allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fantastic Content Protector Free: from n/a through 2.6.
0
Attacker Value
Unknown

CVE-2024-11436

Disclosure Date: December 07, 2024 (last updated December 21, 2024)
The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.4.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2024-53728

Disclosure Date: December 02, 2024 (last updated December 21, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in SEO-Küche Internet Marketing GmbH & Co. KG Protect Your Content allows Stored XSS.This issue affects Protect Your Content: from n/a through 1.0.2.
0
Attacker Value
Unknown

CVE-2024-5921

Disclosure Date: November 27, 2024 (last updated February 20, 2025)
An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install malicious root certificates on the endpoint and subsequently install malicious software signed by the malicious root certificates on that endpoint. Please subscribe to our RSS feed https://security.paloaltonetworks.com/rss.xml to be alerted to new updates to this and other advisories.
0
Attacker Value
Unknown

CVE-2024-9929

Disclosure Date: November 26, 2024 (last updated January 05, 2025)
A vulnerability exists in NSD570 that allows any authenticated user to access all device logs disclosing login information with timestamps.
0
Attacker Value
Unknown

CVE-2024-9928

Disclosure Date: November 26, 2024 (last updated January 05, 2025)
A vulnerability exists in NSD570 login panel that does not restrict excessive authentication attempts. If exploited, this could cause account takeover and unauthorized access to the system when an attacker conducts brute-force attacks against the equipment login. Note that the system supports only one concurrent session and implements a delay of more than a second between failed login attempts making it difficult to automate the attacks.
0
Attacker Value
Unknown

CVE-2024-10781

Disclosure Date: November 26, 2024 (last updated January 05, 2025)
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty value check on the 'api_key' value in the 'perform' function in all versions up to, and including, 6.44. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.
0
Attacker Value
Unknown

CVE-2024-10542

Disclosure Date: November 26, 2024 (last updated January 05, 2025)
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and including, 6.43.2. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.
0
Attacker Value
Unknown

CVE-2022-33862

Disclosure Date: November 25, 2024 (last updated January 05, 2025)
IPP software prior to v1.71 is vulnerable to default credential vulnerability. This could lead attackers to identify and access vulnerable systems.
0